China Mobile International’s network appeared in routes to Salt Typhoon servers at least 192 times between Sept. 22 and 25, 2024 — even after federal regulators had moved to deny or revoke the companies’ authority to provide certain services in the United States.
Salt Typhoon routing ties and the routing dataset
The House China Committee’s nearly 50-page bipartisan investigation found that routing data from Sept. 22–25, 2024 showed China Mobile International in paths to 58 internet-address groups that the Cybersecurity and Infrastructure Security Agency (CISA) had linked to Salt Typhoon servers. The committee said those appearances helped “keep the attacker infrastructure reachable as U.S. defenders sought to shut it down,” while noting the evidence does not definitively link China Mobile USA employees to the operation.
Broadening the scope, the committee identified nearly 109,000 incidents from January 2018 through May 2025 in which Chinese- or Hong Kong-linked networks allegedly claimed U.S. internet addresses without authorization. The panel classified those incidents as high-confidence hijacks of the Border Gateway Protocol (BGP) but acknowledged some may stem from mistakes or poor network management. More than 4,200 of the incidents involved China Mobile–controlled networks; in September 2024, eight incidents originated from the same network that appeared in routes to Salt Typhoon servers and diverted traffic belonging to unnamed U.S. network operators.
What remained inside the United States: points of presence, equipment, and control
The committee found that China Telecom, China Mobile and China Unicom retained equipment, data-center space and private network ties in the United States despite FCC actions from 2019–2022 that denied China Mobile USA’s application to provide international service and revoked related authorizations for China Telecom Americas and China Unicom Americas.
- China Telecom Americas identified 10 active points of presence across seven metropolitan areas; a senior engineering official told investigators about a quarter of the company’s U.S. transmission hardware was still made by Huawei.
- China Mobile USA’s records contained 39 point-of-presence entries across 27 data-center and interconnection facilities, and investigators identified at least 143 active China Mobile network assets in U.S. facilities. One witness described China Mobile USA as “basically a sales team,” and another said it had no network engineers; orders for data-center space and network connections were approved at the company’s Hong Kong headquarters.
- China Unicom Americas had equipment and active connections in roughly 10 U.S. data centers; seven of its eight directors and two of its three senior managers were Chinese Communist Party members, and its U.S. employees used parent-controlled email and computer systems.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we build →Links to CloudRadium, Integrity Technology Group, and i‑SOON
The committee reported specific operational ties between the Chinese carriers and companies previously linked to malicious cyber activity. Subpoenaed records showed China Mobile purchased U.S. data center space and network connections on behalf of CloudRadium — including a four‑year contract valued at $480,000 — and acted in at least one case as a middleman for the Hong Kong hosting provider.
China Unicom appeared in the report as having relationships with Integrity Technology Group and i‑SOON. The panel cited a 2024 U.S. advisory that identified Integrity Tech infrastructure as a control layer for a botnet operated by Flax Typhoon and said China Unicom Beijing network addresses were used to manage that botnet. The committee also said China Unicom and Integrity Tech formalized a cooperation agreement in November 2023 while the botnet was operating.
On i‑SOON, the committee noted that a large collection of purported internal documents surfaced on GitHub in 2024; the Justice Department later charged eight i‑SOON employees and two Chinese police officers in a years-long hacking campaign, alleging cooperation with at least 43 intelligence or police bureaus — charges the report notes have not been proven in court.
Recommendations and expert reactions
The committee recommends giving federal agencies greater authority over equipment and private network arrangements that remain after license revocation, along with targeted removal funding, stronger routing protections and logging requirements for foreign-controlled operators. The panel also urged treating core telecom systems as high‑risk targets requiring closer oversight and tightening rules on foreign-made equipment.
Experts cited in the report offered both support and caution. James Mulvenon, vice president of intelligence at risk advisory firm Pamir Consulting, said the Salt Typhoon campaign “gives the FCC and other agencies more than enough justification to restrict or expel” China’s state telecommunications carriers. Marc Rogers, a telecommunications expert, agreed with many recommendations — including stronger checks on traffic movement — but disputed expanding “rip and replace” programs as economically unrealistic and operationally disruptive. Rogers also warned such measures would succeed only if multiple countries acted in concert.
Cloudflare and unnamed outside cybersecurity experts independently reviewed and verified portions of the committee’s routing analysis, the report said. The committee’s evidence base included subpoenaed company records, eight interviews under oath, federal records, routing data and network infrastructure scans.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: Expect scrutiny on BGP routing protections, logging requirements and tighter operational oversight of network connections tied to foreign-controlled entities; the report highlights concrete routing incidents and retained assets that will inform mitigation priorities.
- Policymakers and regulators: The panel urges expanded authorities to control equipment and private-network arrangements after license revocation and to fund targeted removals — proposals that raise questions about scope, implementation and international coordination.
- Enterprises and data-center operators: The report documents contracts and point-of-presence arrangements — including a $480,000 cloud/data-center contract — underscoring that contractual and leasing relationships can sustain connectivity even after regulatory restrictions on services are imposed.
The report’s central lesson is procedural as much as technical: regulators can ban specified services without necessarily severing the equipment, leases and private agreements that preserve connectivity. The committee calls for new powers and funding to translate license revocations into concrete, physical disconnections — a task the report portrays as politically and operationally difficult but, in its authors’ view, necessary given the scope of the routing incidents and the Salt Typhoon disruptions.
https://www.defenseone.com/threats/2026/08/chinese-telecoms-crackdowns-probe/415208/




